Bhavishya Goswami is a second year student from Dr. Ram Manohar Lohiya National Law University, Lucknow
- Introduction
Digital crimes are at their peak in the era of Artificial Intelligence, where 5.24 billion people are on social media and store their information. One of the most common methods for it is ‘doxxing.’ Doxing is an abbreviation for ‘Dropping Documents’ when another person collects personal information and reveals it publicly to harass, annoy or blackmail. Novel methods of harassment have emerged through doxxing, blurring the fine line between publicly available information and individual security.
In India, no specific provision talks of doxxing, and case laws have just started interpreting it, such as Shaviya Sharma v. Squint Neon. The victims are only left with the Information Technology (IT) Act and Cyber Crime Reporting Portal. Additionally, there are a lot of mental tolls that the victims have to endure. India needs a lot of infrastructural developments vis-à-vis the shared database, advanced judicial interpretations, and technological support to connect all the stakeholders.
- Unmasking the Victim: How Cybercriminals Gather and Exploit Data
Some methods used to dox people include tracking usernames, running a WHOIS search on a domain name, phishing, stalking social media, using data brokers, etc. WHOIS method includes when one’s information is stored within a registry when someone has owned a domain name and is sometimes accessed just through a simple WHOIS search. Another prominent method is tracking IP addresses, which helps the doxers reach out to Internet service providers (ISPs). Another method for it is packet sniffing, in which data is organised in packets as it travels across the internet. When a packet is sniffed, the attacker gets access to its information.
Doxers seek personal information such as phone numbers, home addresses, bank account details, personal imagery, etc. People often use the same or similar usernames for websites and web applications on different accounts. One common feature in these types is the lack of security systems in computer networks worldwide; if it can be improved and merged with social awareness, it will avoid most of the doxxing cases.
- Legal Framework Addressing Doxxing in India
Article 19 of the Indian Constitution states about the freedom of speech and expression; nevertheless, this right can be under reasonable restrictions. Doxxing can attract the punishable offence and penalties under Sections 354 D (online stalking) and 509 (insulting the modesty of a woman), IPC 1860. Apart from this, Section 67 of the Information and Technology Act (“IT Act”) is also applicable, penalising the convicted for publishing or transmitting obscene material in electronic form.
In Justice K.S. Puttaswamy v. Union of India, the apex Court declared that the right to privacy is a fundamental constitutional right derived from Article 21’s right to life and personal liberty. The Court also stated that the current state of technology has resulted in complex privacy breach difficulties, where discovery is extremely difficult because breaches can occur largely ‘invisibly’, with information being accessed, stored, and transmitted at light speed. Furthermore, it was recognised that information is recombinant.
- Psychological and Emotional Toll of Doxxing
As a consequence of doxing, there is always unpredictability in the minds of victims regarding how their information will be used. Victims might be left out even without contacting the authorities out of shame, as it might lead to further public shaming, making them feel powerless. Some victims are so traumatised that they even avoid social media interactions, and victims develop paranoia about their safety. Victims usually evolve with self-doubt, and their confidence drops down to the bottom, primarily when the doxxing occurs, and other social circles become aware of this fact.
These were only intrinsic impacts; however, there are extrinsic psychological and social impactsas well, including the mental toll of constant harassment and cyberbullying post-doxxing as they have to go through relentless public scrutiny. Victims often get blackmailed and harassed not only by the doxxers but by their peer groups as well, and thus, they self-censor themselves to avoid being a target. Reports have shown that victims are susceptible to physical harm, such as stalking or swatting, and have even faced home intrusions or workplace harassment.
- Minimizing the Damage: What to Do if You Are Doxxed
The very first thing a victim should do is report the doxxing to a dependable authority, i.e., the National Cyber Crime Reporting Portal in India. One can save all the proofs, which can be a significant step to start with; it can include screenshots, site URLs, and the pages containing the information. If the publicised information consists of the bank details, contacting the requisite banks will be the most viable option, avoiding financial loss.
One can do a simple step to search the search engines and look for the first name, phone number, last name and street address. Encrypted messaging, when possible, will eliminate numerous sources of surveillance and tracking. Restrict the usage of Email and SMS for formal and academic purposes only, as they are usually not encrypted. One can use a password manager as it would help prevent auto-filling of passwords when clicking on any link, which is the most common form of phishing.
- Recommendations for Legal and Policy Reforms in India
The newly planned act, the Digital India Act, will have more precise provisions vis-à-vis doxxing than the IT Act. Additionally, the Indian Computer Emergency Response Team (CERT-In) is the national agency that deals with cyber security threats. However, despite these, India has no specific legislation or statute for doxxing. In comparison, doxxing is directly prosecuted in the USA under the Computer Fraud and Abuse Act and the Cyberstalking Statute, making it highly advanced compared to Indian jurisprudence, where doxxing is just in a nascent stage.
There is a need for India’s present infrastructure to develop to meet complex needs, as the transnational nature of many doxxing cases can create jurisdictional issues. There is a need for a common database for all the doxxing cases under a protected government portal, and this would make the whole process flexible and streamlined vis-à-vis precedents and jurisdictional issues. Additionally, cooperation between law enforcement agencies and social media platforms, is required to meet the technical expertise needed to investigate doxxing cases.
- Conclusion
In the digital era, information technology regulates every aspect of life, offering cost reduction and streamlined processes, but it has also introduced new forms of cybercrime, particularly doxxing. In the face of the growing prevalence, it goes beyond criminology to ethics and media and communications studies. There needs to be a centralised authority to look at and raise awareness through guidelines about the novel methods invented for doxxing, as a lack of understanding about protecting one’s data is one of the most valid reasons for it. It is contrition that none of our statutes even recognise doxxing as a concept in comparison to the USA and UK where doxxing laws are highly advanced. Aside from this legal concept, it has more far-reaching consequences in the social and psychological life of a victim of doxxing. They usually face sadness, social shame, and a sense of inferiority. The immediate need is for at least specific generalised guidelines from the government. One common database would be invaluable in streamlining the whole process structure. In the age of data, privacy is power – protect it before it’
